Example 3 – the default allow rule

By implementing Example 2 – block all traffic from other networks, we have not really accomplished anything yet. We just blocked access to SALES, MARKETING, and DEVELOPERS from other networks, and pfSense blocks inter-network traffic by default anyway. We need to create a default allow rule for each network to make this work. If such a rule is evaluated after the previously created block rule, it will provide access to both the DMZ network and the internet through the WAN interface.

There are two ways to go about this. pfSense automatically creates Allow LAN to any rules for the LAN interface, which saves us the trouble of providing the LAN network access to other networks. If you have other subnets, most ...

Get Mastering pfSense now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.